Skip to content

Add headless MCP stdio mode and centralized output policy - #239

Open
Mike Krüger (mkrueger) wants to merge 19 commits into
mainfrom
dev/mkrueger/mcp_stdio
Open

Mike Krüger (mkrueger) wants to merge 19 commits into
mainfrom
dev/mkrueger/mcp_stdio

Conversation

@mkrueger

@mkrueger Mike Krüger (mkrueger) commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Adds --mcp-stdio, a headless MCP server for clients that launch and own the process, and centralizes shell output so stdio, --quiet, and machine mode follow one policy.

Why

HTTP MCP (--mcp [port]) needs a listening localhost port that any local user can reach, and its lifetime is separate from the client. With stdio, the client owns the process and its pipes: no port, per-client state, and shutdown when the client closes stdin.

  • easy local setup/no open http
  • clear life cycle with seperate by client states

Open Question: If it is really needed.

Stdio contract

  • stdin: MCP JSON-RPC requests only. Commands can never read it.
  • stdout: MCP messages only. Managed console output is redirected to stderr before startup, and Spectre is configured for stderr without ANSI.
  • stderr: startup errors, logs, warnings, and required instructions (such as device-code sign-in).
  • Closing stdin stops the server, including with open subscriptions or pending confirmations.

Supported: startup --connect/--database/--container, protocol 2025-11-25 and earlier (initialize) and 2026-07-28 (server/discover), destructive-command confirmations, and location subscriptions. Rejected at startup: --mcp, --lsp, -c, -k, --clear-history, and --mcp-stdio passed through a response file.

Removed from the tool list, help, and direct invocation, including aliases: jq, theme, and commands restricted from MCP that cannot be confirmed (exit, edit, watch, welcome, sproc, udf, trigger). Destructive commands (delete, rm, rmdb, rmcon) stay available through MCP confirmation. HTTP mode keeps its existing tool list.

Stdio mode does not load or record shell history.

Sign-in never opens a browser. A headless server has no user at the terminal, and the browser launcher (for example xdg-open) inherits the process stdout. --tenant/--hint connections use device code sign-in, and endpoint-only connections use DefaultAzureCredential without its interactive browser step. Cancelling the tool call ends a pending sign-in.

Centralized output

User-facing output now goes through ShellOutput with an explicit category: Information, Progress, Warning, Error, RequiredInstruction, or Result.

  • --quiet suppresses information, progress, banners, and command echoes. Results, warnings, errors, and required instructions stay visible, including code previews shown before a confirmation prompt.
  • Machine-mode stdout carries only the interpreter's final result. Tables that commands draw for interactive users no longer appear there.
  • theme, help, and edit now throw errors instead of printing and returning them. In machine mode their failures previously exited with code 1 and no message; they now produce one {"status":"error",...} object on stderr. Interactive and script errors are reported once.
  • New analyzer rule CZ0003 fails the build on direct Console/AnsiConsole output outside ShellOutput. Line-editor drawing keeps scoped suppressions.

Commits

  1. Add headless MCP stdio mode
  2. Disable shell history in MCP stdio mode
  3. Centralize shell output through a category-based policy
  4. Update Copilot instructions for MCP stdio and output policy
  5. Keep MCP stdio sign-in non-interactive

Known limitations

  • Device-code instructions appear only on stderr, so someone must read them from the client's server log. Surfacing them through MCP could be a follow-up.
  • Stdio isolates the protocol stream but is not a sandbox. The client still acts with the process owner's file and Cosmos permissions.

Reserve stdin and stdout for MCP, support confirmations and subscriptions, and stop on input EOF. Omit unsupported commands from stdio tools and help while preserving HTTP behavior.
Skip history loading and command recording for stdio servers while preserving interactive and HTTP history and explicit diagnostic logging.
Route all user-facing output through ShellOutput so --quiet, machine mode, and MCP stdio are decided in one place. Quiet suppresses information and progress but keeps results, warnings, errors, and required instructions. Machine-mode stdout carries only the interpreter result, and theme, help, and edit failures are reported once through the central error reporter. Add analyzer rule CZ0003 to reject direct console output.
Describe the HTTP and stdio MCP transports and require user-facing output to go through ShellOutput.
Never open a browser in stdio mode: tenant or hint connections use device code sign-in with instructions on stderr, and endpoint-only connections use DefaultAzureCredential without its interactive browser step.
Comment thread CosmosDBShell.Tests/UtilTest/ShellOutputTests.cs Fixed
Comment thread CosmosDBShell/Program.cs Fixed
Comment thread CosmosDBShell/Program.cs
Comment thread CosmosDBShell.Tests/Integration/McpStdioProcessTests.cs
Comment thread CosmosDBShell.Tests/Integration/McpStdioProcessTests.cs
Comment thread CosmosDBShell.Tests/Integration/McpStdioProcessTests.cs Fixed
Comment thread CosmosDBShell.Tests/Integration/McpStdioProcessTests.cs Fixed
Comment thread CosmosDBShell.Tests/Integration/McpStdioProcessTests.cs Fixed
Comment thread CosmosDBShell.Tests/Integration/McpStdioProcessTests.cs Fixed
@github-code-quality

github-code-quality Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Code Coverage Overview

Languages: C#

C# / code-coverage/dotnet

The overall line coverage in commit 0abc080 in the dev/mkrueger/mcp_std... branch is 67%. The line coverage in commit 3a9dc25 in the main branch is 66%.

Show a line coverage summary of the most impacted files.
File main 3a9dc25 dev/mkrueger/mcp_std... 0abc080 +/-
D:\a\CosmosDBSh...elcomeScreen.cs 96% 78% -18%
D:\a\CosmosDBSh...olOperations.cs 95% 97% +2%
D:\a\CosmosDBSh...ThemeCommand.cs 60% 62% +2%
D:\a\CosmosDBSh...lInterpreter.cs 73% 76% +3%
D:\a\CosmosDBSh...hell\Program.cs 80% 83% +3%
D:\a\CosmosDBSh...\EditCommand.cs 5% 11% +6%
D:\a\CosmosDBSh...nnectCommand.cs 22% 30% +8%
D:\a\CosmosDBSh...oInputStream.cs 0% 53% +53%
D:\a\CosmosDBSh...\ShellOutput.cs 0% 88% +88%
D:\a\CosmosDBSh...StartupInput.cs 0% 89% +89%

Updated October 09, 2026 08:48 UTC

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

LSP conflicts can bypass validation, localization is unsynchronized, and several machine-mode failures emit non-JSON diagnostics.

Review effort: Balanced
Findings: 6 High severity · 1 Medium severity

Open (7)
What changed in this PR

Adds client-owned MCP stdio transport and centralizes shell output policy for interactive, quiet, machine, and protocol modes.

Changes:

  • Adds headless MCP stdio hosting, confirmation, subscriptions, authentication, and history isolation.
  • Routes command presentation through ShellOutput and enforces it with analyzer CZ0003.
  • Updates documentation, localization, and automated coverage.
File Description
README.md Documents stdio and output behavior.
l10n/​CosmosDBShell.json Adds canonical localized strings.
docs/​navigation.md Documents startup and machine-mode options.
docs/​mcp.md Adds comprehensive stdio guidance.
docs/​connect.md Documents headless authentication.
CosmosDBShell/​Program.cs Configures and launches stdio mode.
CosmosDBShell/​lang/​en.ftl Adds English UI strings.
CosmosDBShell/​GlobalSuppressions.cs Removes obsolete output suppressions.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Mcp/​ToolOperations.cs Adds stdio filtering and confirmation handling.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Mcp/​StdioInputStream.cs Stops the host on stdin EOF.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Mcp/​McpServer.cs Adds stream transport hosting.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Mcp/​LocationResourceSubscriptions.cs Supports stdio subscriptions.
CosmosDBShell/​Azure.Data.Cosmos.Shell.KeyBindings/​ReverseSearchHistoryCommand.cs Scopes analyzer suppressions.
CosmosDBShell/​Azure.Data.Cosmos.Shell.KeyBindings/​ClearScreenCommand.cs Uses centralized screen clearing.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Core/​ShellOutput.cs Implements category-based output routing.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Core/​OutputPolicy.cs Defines output visibility and destination.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Core/​CosmosCompletionRenderer.cs Scopes editor-output suppression.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Core/​CommandRunner.cs Supports command removal by predicate.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​WhoamiCommand.cs Centralizes result rendering.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​WatchCommand.cs Applies output categories to streaming.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​UdfCommand.cs Centralizes UDF output.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​TtlCommand.cs Categorizes update messages.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​TriggerCommand.cs Centralizes trigger output.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​ThroughputCommand.cs Centralizes throughput rendering.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​ThemeCommand.cs Routes output and throws failures.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​SprocCommand.cs Centralizes stored-procedure output.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​RmDbCommand.cs Centralizes removal results.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​RmContainerCommand.cs Centralizes removal results.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​RmCommand.cs Categorizes warnings and results.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​ReplaceCommand.cs Categorizes bulk replacement diagnostics.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​QueryCommand.cs Centralizes query rendering and warnings.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​PwdCommand.cs Centralizes location rendering.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​PatchCommand.cs Categorizes success output.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​MakeItemCommand.cs Categorizes item-write diagnostics.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​MakeDbCommand.cs Centralizes creation results.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​MakeContainerCommand.cs Centralizes creation results.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​ListCommand.cs Centralizes list rendering.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​InfoCommand.cs Centralizes informational tables.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​IndexCommand.cs Categorizes update messages.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​ImportCommand.cs Categorizes import diagnostics.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​HelpCommand.cs Centralizes help output and failures.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​FtabCommand.cs Centralizes table rendering.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​ExportCommand.cs Categorizes export completion.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​EditCommand.cs Routes output and throws failures.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​DoctorCommand.cs Centralizes diagnostic rendering.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​DisconnectCommand.cs Centralizes disconnect results.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​DirCommand.cs Centralizes directory rendering.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​ConnectCommand.cs Centralizes connection output.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​ConflictCommand.cs Categorizes update output.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​ClsCommand.cs Uses centralized screen clearing.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​CdCommand.cs Categorizes navigation messages.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​CanICommand.cs Centralizes authorization rendering.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​BucketCommand.cs Categorizes bucket output.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​BatchExecutor.cs Centralizes batch results and errors.
CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​BatchCommand.cs Centralizes batch status rendering.
CosmosDBShell.Tests/​UtilTest/​ShellOutputTests.cs Tests output routing policy.
CosmosDBShell.Tests/​UtilTest/​OutputPolicyTests.cs Tests stdio machine mode.
CosmosDBShell.Tests/​ToolOperationsCallToolTests.cs Tests stdio tools and confirmation scope.
CosmosDBShell.Tests/​StdioInputStreamTests.cs Tests EOF shutdown behavior.
CosmosDBShell.Tests/​Shell/​ShellConfigDirectoryTests.cs Tests disabled history loading.
CosmosDBShell.Tests/​Parser/​StatementPositionalErrorTests.cs Preserves returned-error location coverage.
CosmosDBShell.Tests/​McpLocationSubscriptionTests.cs Tests stdio location subscriptions.
CosmosDBShell.Tests/​McpConfirmationTests.cs Tests stdio confirmation elicitation.
CosmosDBShell.Tests/​Integration/​ShellProcessTests.cs Tests machine and startup output.
CosmosDBShell.Tests/​Integration/​McpStdioProcessTests.cs Exercises real stdio processes.
CosmosDBShell.Tests/​CommandTests/​ThemeCommandTests.cs Updates thrown-error assertions.
CosmosDBShell.Tests/​CommandTests/​ThemeCommandDispatchTests.cs Updates theme failure tests.
CosmosDBShell.Tests/​CommandTests/​ConnectCommandTests.cs Tests non-browser authentication.
CosmosDBShell.Analyzer/​GlobalSuppressions.cs Registers analyzer release suppression.
CosmosDBShell.Analyzer/​DirectConsoleOutputAnalyzer.cs Adds direct-output analyzer CZ0003.
CHANGELOG.md Records user-visible behavior.
.github/​copilot-instructions.md Documents repository stdio constraints.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread CosmosDBShell/Azure.Data.Cosmos.Shell.Commands/BucketCommand.cs Outdated
Comment thread CosmosDBShell/Azure.Data.Cosmos.Shell.Commands/ImportCommand.cs Outdated
Comment thread CosmosDBShell/Azure.Data.Cosmos.Shell.Commands/MakeItemCommand.cs Outdated
Comment thread CosmosDBShell/Azure.Data.Cosmos.Shell.Commands/ReplaceCommand.cs Outdated
Comment thread CosmosDBShell/Azure.Data.Cosmos.Shell.Commands/ThemeCommand.cs Outdated
Comment thread CosmosDBShell/lang/en.ftl Outdated
Comment thread CosmosDBShell/Program.cs Outdated
Cancel startup on stdin EOF, enforce a shared 60-second connection and navigation deadline, and preserve buffered protocol input. Add lifecycle and cancellation regression tests and update documentation.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 6, 2026 08:15
Comment thread CosmosDBShell/Azure.Data.Cosmos.Shell.Mcp/StdioStartupInput.cs Fixed
Comment thread CosmosDBShell/Program.cs Fixed
Comment thread CosmosDBShell/Azure.Data.Cosmos.Shell.Mcp/StdioStartupInput.cs Fixed

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Attached or response-file LSP options can bypass stdio conflict validation and start the wrong transport.

Review effort: Balanced
Findings: 6 High severity · 2 Medium severity

Open (8)
Previously missed (1)

In code that hasn't changed since last review

Low severity Capitalize “Interactive-only” at sentence start

README.md:47

Capitalize “Interactive-only” because it begins a new sentence.

Comment thread CosmosDBShell.Tests/StdioStartupInputTests.cs
Copilot AI balanced review requested due to automatic review settings October 6, 2026 12:27
Comment thread CosmosDBShell.Tests/Integration/McpStdioProcessTests.cs Fixed
Comment thread CosmosDBShell.Tests/Integration/McpStdioProcessTests.cs Fixed
Comment thread CosmosDBShell.Tests/Integration/McpStdioProcessTests.cs Fixed
Comment thread CosmosDBShell.Tests/Integration/ShellProcessTests.cs Fixed
Comment thread CosmosDBShell.Tests/Integration/ShellProcessTests.cs Fixed

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread CosmosDBShell/Program.cs
Comment thread CosmosDBShell/Azure.Data.Cosmos.Shell.Mcp/StdioStartupInput.cs Outdated
Comment thread README.md Outdated
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 6, 2026 12:38
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Comment thread CosmosDBShell/Azure.Data.Cosmos.Shell.Mcp/StdioStartupInput.cs

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Headless default authentication still permits broker-based interactive sign-in despite the no-browser contract.

Review effort: Balanced
Findings: 1 High severity

Open (1)
Resolved since last review (3)

Comment thread CosmosDBShell.Tests/CommandTests/ConnectCommandTests.cs
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 6, 2026 15:31
Copilot AI balanced review requested due to automatic review settings October 6, 2026 16:52

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Response-file validation can be bypassed by early LSP startup, and startup input backpressure can delay EOF cancellation.

Review effort: Balanced
Findings: None

Previously missed (2)

In code that hasn't changed since last review

Medium severity Prevent startup stdin deadlock from pipe backpressure

CosmosDBShell/​Azure.Data.Cosmos.Shell.Mcp/​StdioStartupInput.cs:14

The default Pipe applies bounded writer backpressure, but nothing consumes Input until startup connection/navigation finishes. If a client queues more than the pipe threshold and then closes stdin, CopyToAsync can block flushing into the pipe before it observes EOF, so StartupToken is not cancelled until the 60-second deadline. Use a startup buffering strategy that keeps draining stdin through EOF (while bounding/spooling safely), and cover an input larger than the pipe threshold.

Medium severity Reject response-file stdio before LSP early return

CosmosDBShell/​Program.cs:79

This validation still runs after the early LSP return above. If a response file contains --mcp-stdio and the direct command line also contains --lsp or --stdio, the process starts LSP at lines 63–67 and never reaches this rejection. Parse and reject response-file stdio requests before any protocol-mode early return so the documented direct-command-line and incompatibility rules cannot be bypassed.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 6, 2026 17:05
Comment thread CosmosDBShell/Azure.Data.Cosmos.Shell.Mcp/StdioStartupInput.cs Fixed

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Response-file expansion can still enable stdio when a directly supplied false-valued option bypasses the guard.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)

Comment thread CosmosDBShell/Program.cs Outdated
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 6, 2026 17:22

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Successful non-strict directory validation suppresses warnings in machine and quiet modes, contrary to the documented output policy.

Review effort: Balanced
Findings: None

Resolved since last review (1)
Previously missed (1)

In code that hasn't changed since last review

Medium severity Preserve validation warnings in successful machine-mode scans

CosmosDBShell/​Azure.Data.Cosmos.Shell.Commands/​ThemeCommand.cs:524

In machine mode this guard suppresses every validation warning, even when non-strict directory validation succeeds. That bypasses the new category policy and contradicts the documented --quiet contract that warnings remain visible on stderr; single-file validation already preserves warnings on successful machine-mode runs. Buffer the warnings while scanning and emit them after the loop only when invalidCount == 0 (while retaining the single structured error when validation fails).

Address the remaining PR #239 review overview finding without adding warning lines before failed machine-mode scans.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 7, 2026 13:09
@mkrueger

Copy link
Copy Markdown
Collaborator Author

Fixed the directory-validation warning handling. Successful machine-mode and quiet scans now emit warnings on stderr after the scan; failed scans still emit only the structured error. Main is merged.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The startup input spool can persist buffered protocol data when an uninterruptible stdin read prevents cleanup.

Review effort: Balanced
Findings: 1 High severity

Open (1)

Comment thread CosmosDBShell/Azure.Data.Cosmos.Shell.Mcp/StdioStartupInput.cs Outdated
Preserve static MCP resource capabilities and release the private delete-on-close startup spool independently of blocked stdin reads.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 9, 2026 07:36

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Unbounded machine-mode watch sessions silently discard every change-feed item.

1 open finding
1 resolved since last review

🧠 Review effort: Balanced

Comment thread CosmosDBShell/Azure.Data.Cosmos.Shell.Commands/WatchCommand.cs
Address the watch output regression in #239.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 9, 2026 07:56

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

CZ0003 currently breaks the main build, and startup stdin buffering can exhaust temporary storage.

2 open findings
1 resolved since last review

🧠 Review effort: Balanced

Comment thread CosmosDBShell.Analyzer/DirectConsoleOutputAnalyzer.cs
Comment thread CosmosDBShell/Azure.Data.Cosmos.Shell.Mcp/StdioStartupInput.cs
Limit the startup spool to 8 MiB and report input overflow in #239.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI balanced review requested due to automatic review settings October 9, 2026 08:41

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

It changes security-sensitive transport, authentication, confirmation, shutdown, and output contracts across the application.

0 open findings

2 resolved since last review

🧠 Review effort: Balanced

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants